FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

For risk managers, underwriters and compliance leads deciding whether to trust an AI agent with compliance work

Run your AI agent through end-to-end compliance workflows. See the step where it derails.

AI Agent Compliance Workflow Tester gives you end-to-end compliance workflows to run your own AI agent through, and scores its answer step by step: completed, derailed at a named step, or failed, with the rule behind every step.

  1. 1You run your own agent on our specimen inputs and paste its answer or transcript. Nothing connects to your agent, we never ask for credentials or real records, and nothing you paste leaves your browser unless you save it.
  2. 2Every step names the rule it rests on, cited to its clause and edition.
  3. 3This shows which steps this agent completed on this scenario version. It does not show that the agent is safe, compliant or fit for any other task.
The record an underwriting file or a model risk committee asks for: which step an agent got wrong, and the clause behind that step. The same inputs on every run, and the agent never leaves your hands.

Score an answer

The run, as you enter it (never filled in by this page)

Scoring happens in this browser: nothing you paste leaves it unless you save the run.

How it works

  1. 01

    Download the agent pack

    Each scenario has a free pack: a brief, the inputs (every one marked SPECIMEN) and an answer template. Give your agent the pack, never the scenario page: the page is the answer key.

  2. 02

    Run your agent

    In your own environment, with your own prompt and tools. Ask it to print its answer between two marker lines. Run it ten times if you like; agents are not deterministic.

  3. 03

    Paste and score

    Paste the answer or the whole transcript. Each step gets four checks (rule, decision, record, actions), the first failing step decides the result, and the sheet carries a fingerprint anyone can re-check.

The eight scenarios

Vendor onboarding with a bank detail change, a phished mailbox under the Privacy Act, an NDIS worker barred mid-shift, a ransomware payment report, an APRA insurer's provider incident, an AI claims agent's impact assessment, a material service provider, and an auditor's access review request. Filter them by process, framework, jurisdiction and risk.

KC-01 · v1.0

Vendor onboarding under ISO/IEC 27001 and SOC 2

A franchise head office onboards a cloud vendor that will hold franchisee identity documents and bank details.

Process
Vendor onboarding
Frameworks
ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), plus the organisation's own procedure
Jurisdiction
Australia, International
Steps
8
Risks exercised
injected input, escalation, unrequested action, payment redirection, data access
KC-02 · v1.0

Data breach under the Privacy Act and the Essential Eight

A small physiotherapy group finds a phished mailbox full of client referral letters was read by an attacker.

Process
Data breach response
Frameworks
Privacy Act 1988 (Cth), Essential Eight Maturity Model, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
injected input, escalation, unrequested action, clock arithmetic, data counting
KC-03 · v1.0

Contractor offboarding under the NDIS rules

A registered NDIS provider learns a labour-hire support worker is under an interim bar, a day after an alleged assault.

Process
Contractor offboarding
Frameworks
NDIS (Practice Standards: Worker Screening) Rules 2018, NDIS (Incident Management and Reportable Incidents) Rules 2018, NDIS Practice Standards and Quality Indicators, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
injected input, escalation, unrequested action, clock arithmetic, business days, data access
KC-04 · v1.0

Ransomware payment report under the Cyber Security Act 2024

A freight company's negotiator pays a ransom on its behalf; the 72-hour report clock is running.

Process
Incident reporting
Frameworks
Cyber Security Act 2024 (Cth), Essential Eight Maturity Model, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
escalation, unrequested action, clock arithmetic
KC-05 · v1.0

A claims vendor incident at an APRA-regulated insurer (CPS 234, CPS 230, Privacy Act)

An insurer's claims platform provider is breached and the platform stays down past its tolerance.

Process
Data breach response
Frameworks
APRA CPS 234 Information Security, APRA CPS 230 Operational Risk Management, Privacy Act 1988 (Cth), plus the organisation's own procedure
Jurisdiction
Australia
Steps
6
Risks exercised
escalation, unrequested action, clock arithmetic, third-party dependency
KC-07 · v1.0

Onboarding an offshore claims provider under CPS 230 and CPS 234

An insurer plans to outsource claims handling to a provider whose team works overseas.

Process
Vendor onboarding
Frameworks
APRA CPS 230 Operational Risk Management, APRA CPS 234 Information Security, plus the organisation's own procedure
Jurisdiction
Australia
Steps
7
Risks exercised
escalation, unrequested action, third-party dependency, offshoring
KC-08 · v1.0

An auditor asks for access review and leaver evidence (ISO/IEC 27001 and SOC 2)

A service auditor asks for the quarter's access review and proof every leaver lost access on time.

Process
Audit evidence request
Frameworks
ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), plus the organisation's own procedure
Jurisdiction
Australia, International
Steps
4
Risks exercised
escalation, unrequested action, data counting, business days, record integrity

What the sheet is for

A cyber or technology underwriter asking how an insured tests its agents, a model risk committee validating an agent before deployment, a franchise head office deciding whether an agent may onboard suppliers: each wants a record of what was tested, on which version, with which result. The score sheet is that record: the scenario and version, the agent as you entered it, every step with its four checks, the rule behind each step and the reason the first failing step failed.

Each public scenario also has held-out variants on the paid plans: one fact changed so the expected decision changes, kept out of every public file, so an agent tuned to the public answer key shows it. How scoring works.

Prices

Every scenario page, every agent pack, the scorer (one run, many runs, compare, re-verify, evidence) and the specimen runs are free. Solo USD 99 a month saves runs and adds the held-out variants, the full pack and the committee summary; Team USD 299 adds five people and the change log; Underwriter USD 990 keeps up to 25 insureds or clients apart. Pricing.